S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2014-8799 Scanner

Detects 'Directory Traversal' vulnerability in DukaPress plugin for Wordpress affects v. before 2.5.4.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
5.0
CVSS
Description

Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter to lib/dp_image.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Sep 18, 2026View on NVD →
Detail

The DukaPress plugin is an e-commerce solution for WordPress that enables users to easily sell products and services on their websites. With DukaPress, users can create product pages, manage orders, and process payments seamlessly. However, a vulnerability in version 2.5.4 and below of DukaPress has been discovered that can compromise the security of websites using this plugin.

The vulnerability, with the code CVE-2014-8799, is a directory traversal bug found in the dp_img_resize function in php/dp-functions.php. This bug allows attackers to read arbitrary files through a ".." in the 'src' parameter to lib/dp_image.php. In other words, this vulnerability enables attackers to access sensitive files and data on the targeted website.

When exploited, this vulnerability can result in attackers gaining access to sensitive files such as password files, configuration files, and other sensitive data that can lead to a complete website takeover. This vulnerability can also lead to unauthorized access to customer information, which can result in a data breach.

In conclusion, it is essential to stay informed about vulnerabilities in digital assets, such as websites. With the pro features of the s4e.io platform, it is easy to quickly learn about vulnerabilities and take action to protect your online assets. Stay vigilant and take proactive measures to protect your website from malicious attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners and administrators should take the following precautions:

  • Upgrade to the latest version of DukaPress or remove the plugin if it is not being used.
  • Implement website hardening techniques such as web application firewalls to detect and block directory traversal attacks.
  • Use a content security policy (CSP) to limit the types of scripts and resources that can be loaded by a website.
  • Regularly scan the website for vulnerabilities and patch them as soon as they are discovered.
  • Conduct regular security awareness training for website users and administrators to prevent them from falling victim to social engineering attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2014-8799 scanner - Directory Traversal vulnerability in DukaPress plugin for Wordpress | S4E